Cybercriminals train AI chatbots for phishing, malware attacks

Share:

In the wake of WormGPT, a ChatGPT clone trained on malware-focused data, a new generative artificial intelligence hacking tool called FraudGPT has emerged, and at least another one is under development that is allegedly based on Google’s AI experiment, Bard.

Both AI-powered bots are the work of the same individual, who appears to be deep in the game of providing chatbots trained specifically for malicious purposes ranging from phishing and social engineering, to exploiting vulnerabilities and creating malware.

FraudGPT came out on July 25 and has been advertised on various hacker forums by someone with the username CanadianKingpin12, who says the tool is intended for fraudsters, hackers, and spammers.

FraudGPT promoted on hacker forum
FraudGPT promoted on hacker forum (SlashNext)

Next-gen cybercrime chatbots

An investigation from researchers at cybersecurity company SlashNext, reveals that CanadianKingpin12 is actively training new chatbots using unrestricted data sets sourced from the dark web or basing them on sophisticated large language models developed for fighting cybercrime.

In private conversations, CanadianKingpin12 said that they were working on DarkBART – a “dark version” of Google’s conversational generative artificial intelligence chatbot.

The researchers also learned that the advertiser also had access to another large language model named DarkBERT developed by South Korean researchers and trained on dark web data but to fight cybercrime.

DarkBERT is available to academics based on relevant email addresses but SlashNext highlights that this criteria is far from a challenge for hackers or malware developers, who can get access to an email address from an academic institution for around $3.

EDU email account access available for $3
.EDU email accounts for sale
source: SlashNext

SlashNext researchers shared that CanadianKingpin12 said that the DarkBERT bot is “superior to all in a category of its own specifically trained on the dark web.” The malicious version has been tuned for:

  • Creating sophisticated phishing campaigns that target people’s passwords and credit card details
  • Executing advanced social engineering attacks to acquire sensitive information or gain unauthorized access to systems and networks.
  • Exploiting vulnerabilities in computer systems, software, and networks.
  • Creating and distributing malware.
  • Exploiting zero-day vulnerabilities for financial gain or systems disruption.

As CanadianKingpin12 said in private messages with the researchers, both DarkBART and DarkBERT will have live internet access and seamless integration with Google Lens for image processing.

To demonstrate the potential of the malicious version of DarkBERT, the developer created the following video:

It is unclear if CanadianKingpin12 modified the code in legitimate version of DarkBERT or just obtained access to the model and simply leveraged it for malicious use.

No matter the origin of DarkBERT and the validity of the threat actor’s claims, the trend of using generative AI chatbots is growing and the adoption rate is likely to increase, too, as it can provide an easy solution for less capable threat actors or for those that want to expand operations to other regions and lack the language skills.

With hackers already having access to two such tools that can assist with executing advanced social engineering attacks and their development in less than a month, “underscores the significant influence of malicious AI on the cybersecurity and cybercrime landscape,” SlashNext researchers believe.

 

(c) Lawrence Abrams

Leave a Comment

Your email address will not be published. Required fields are marked *

loader-image
London, GB
10:18 pm, May 23, 2025
weather icon 14°C
L: 13° | H: 15°
overcast clouds
Humidity: 65 %
Pressure: 1016 mb
Wind: 11 mph SW
Wind Gust: 0 mph
UV Index: 0
Precipitation: 0 mm
Clouds: 87%
Rain Chance: 0%
Visibility: 10 km
Sunrise: 4:57 am
Sunset: 8:56 pm
DailyHourly
Daily ForecastHourly Forecast
Tomorrow 10:00 pm
weather icon
13° | 15°°C 1 mm 100% 13 mph 98 % 1016 mb 0 mm/h
Sun May 25 10:00 pm
weather icon
13° | 19°°C 0.61 mm 61% 18 mph 90 % 1015 mb 0 mm/h
Mon May 26 10:00 pm
weather icon
10° | 18°°C 0.52 mm 52% 13 mph 79 % 1018 mb 0 mm/h
Tue May 27 10:00 pm
weather icon
13° | 21°°C 1 mm 100% 15 mph 94 % 1017 mb 0 mm/h
Wed May 28 10:00 pm
weather icon
14° | 19°°C 0.25 mm 25% 16 mph 89 % 1022 mb 0 mm/h
Tomorrow 1:00 am
weather icon
13° | 14°°C 0.51 mm 51% 7 mph 71 % 1016 mb 0 mm/h
Tomorrow 4:00 am
weather icon
10° | 12°°C 1 mm 100% 7 mph 87 % 1015 mb 0 mm/h
Tomorrow 7:00 am
weather icon
13° | 13°°C 1 mm 100% 10 mph 98 % 1013 mb 0 mm/h
Tomorrow 10:00 am
weather icon
16° | 16°°C 0.7 mm 70% 10 mph 97 % 1012 mb 0 mm/h
Tomorrow 1:00 pm
weather icon
22° | 22°°C 0.17 mm 17% 13 mph 62 % 1012 mb 0 mm/h
Tomorrow 4:00 pm
weather icon
21° | 21°°C 0 mm 0% 13 mph 60 % 1011 mb 0 mm/h
Tomorrow 7:00 pm
weather icon
19° | 19°°C 0.2 mm 20% 10 mph 76 % 1011 mb 0 mm/h
Tomorrow 10:00 pm
weather icon
16° | 16°°C 0.2 mm 20% 11 mph 90 % 1011 mb 0 mm/h
Name Price24H (%)
Bitcoin(BTC)
€95,447.62
-2.42%
Ethereum(ETH)
€2,241.80
-3.63%
Tether(USDT)
€0.88
-0.01%
XRP(XRP)
€2.05
-3.77%
Solana(SOL)
€156.26
-0.52%
USDC(USDC)
€0.88
0.00%
Dogecoin(DOGE)
€0.203515
-3.57%
Shiba Inu(SHIB)
€0.000013
-4.10%
Pepe(PEPE)
€0.000013
2.29%
Peanut the Squirrel(PNUT)
€0.308360
-2.17%
Scroll to Top